Splunk Search

How to overlay daily avg on count per day using timechart?


I have the basic search of for count by day

| bin _time span=1d 
| timechart count

How can I overlay the daily avg of count per day?


0 Karma

Ultra Champion
| tstats count where index=foo prestats=t by _time span=1d
| timechart count
| eventstats avg(count) as daily_avg

Visualization with overlay daily_avg
How about this?


Can you please elaborate, or possibly provide some examples? The count per day is just that: a single value. What are you trying to average? The timechart command itself allows bucketing by day with the span=1d option, and can perform statistical aggregations including avg and count.

0 Karma